New GravityRAT spyware found on messaging apps targets WhatsApp backups
ESET researchers have uncovered an updated version of the Android-based GravityRAT spyware, which is being distributed through messaging apps BingeChat and Chatico. The spyware is a remote access tool that was previously used in targeted attacks against users in India. The trojanized BingeChat app is available for download from a website that presents it as a free messaging and file sharing service.
This version of GravityRAT has been enhanced with two new capabilities: it can receive commands to delete files and exfiltrate WhatsApp backup files. The malicious apps also provide legitimate chat functionality based on the open-source OMEMO Instant Messenger app. It is not yet known how potential victims were lured to, or otherwise discovered, the malicious website.
The discovery of this updated version of GravityRAT highlights the ongoing threat posed by spyware and other forms of malware. Users are advised to be cautious when downloading apps from third-party websites and to only install apps from trusted sources such as Google Play. It is also recommended to keep devices updated with the latest security patches and to use a reputable mobile security solution to protect against malware.